{"schema_version":1,"title":"OneDev vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 6 vulnerabilities in OneDev: 0 in the last 7 days and 0 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-49248, was published on 18 June 2026. 1 technology has a page of its own.","url":"https://junglewise.ai/threats/vendors/onedev","json_url":"https://junglewise.ai/threats/vendors/onedev.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/vendors/onedev","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"vendor","counts":{"high":0,"all_time":6,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":0,"last_365_days":6},"latest":[{"cve":"CVE-2026-49248","cvss":8.3,"slug":"cve-2026-49248-onedev-arbitrary-file-write-via-absolute-path-symlink-in-tarutils","title":"OneDev arbitrary file write via absolute path symlink in TarUtils","severity":"info","exploited":false,"published_at":"2026-06-18T21:16:29.5+00:00","url":"https://junglewise.ai/threats/cve-2026-49248-onedev-arbitrary-file-write-via-absolute-path-symlink-in-tarutils"},{"cve":"CVE-2026-11441","cvss":6.3,"slug":"cve-2026-11441-theonedev-onedev-improper-authorization-in-pull-request-handler","title":"theonedev OneDev improper authorization in Pull Request Handler","severity":"medium","exploited":false,"published_at":"2026-06-06T18:16:53.443+00:00","url":"https://junglewise.ai/threats/cve-2026-11441-theonedev-onedev-improper-authorization-in-pull-request-handler"},{"cve":"CVE-2026-11440","cvss":6.3,"slug":"cve-2026-11440-theonedev-onedev-improper-authorization-in-rest-api-default","title":"theonedev OneDev improper authorization in REST API default-branch endpoint","severity":"medium","exploited":false,"published_at":"2026-06-06T18:16:53.243+00:00","url":"https://junglewise.ai/threats/cve-2026-11440-theonedev-onedev-improper-authorization-in-rest-api-default"},{"cve":"CVE-2026-11439","cvss":6.3,"slug":"cve-2026-11439-theonedev-onedev-improper-authorization-in-parent-project-handler","title":"theonedev OneDev improper authorization in Parent Project Handler","severity":"medium","exploited":false,"published_at":"2026-06-06T18:16:53.063+00:00","url":"https://junglewise.ai/threats/cve-2026-11439-theonedev-onedev-improper-authorization-in-parent-project-handler"},{"cve":"CVE-2026-11438","cvss":6.3,"slug":"cve-2026-11438-theonedev-onedev-improper-authorization-in-project-fork","title":"theonedev OneDev improper authorization in project fork functionality","severity":"medium","exploited":false,"published_at":"2026-06-06T17:16:41.713+00:00","url":"https://junglewise.ai/threats/cve-2026-11438-theonedev-onedev-improper-authorization-in-project-fork"},{"cve":"CVE-2026-44647","cvss":7.1,"slug":"cve-2026-44647-onedev-path-traversal-in-git-lfs-pointer-resolution","title":"OneDev path traversal in Git LFS pointer resolution","severity":"info","exploited":false,"published_at":"2026-05-14T21:16:46.967+00:00","url":"https://junglewise.ai/threats/cve-2026-44647-onedev-path-traversal-in-git-lfs-pointer-resolution"}],"vendor":{"hub":true,"name":"OneDev","slug":"onedev","homepage":"https://onedev.io/","description":"OneDev is an open-source self-hosted Git server with built-in CI/CD and kanban boards.","url":"https://junglewise.ai/threats/vendors/onedev"},"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0}],"most_severe":[{"cve":"CVE-2026-11441","cvss":6.3,"slug":"cve-2026-11441-theonedev-onedev-improper-authorization-in-pull-request-handler","title":"theonedev OneDev improper authorization in Pull Request Handler","severity":"medium","exploited":false,"published_at":"2026-06-06T18:16:53.443+00:00","url":"https://junglewise.ai/threats/cve-2026-11441-theonedev-onedev-improper-authorization-in-pull-request-handler"},{"cve":"CVE-2026-11440","cvss":6.3,"slug":"cve-2026-11440-theonedev-onedev-improper-authorization-in-rest-api-default","title":"theonedev OneDev improper authorization in REST API default-branch endpoint","severity":"medium","exploited":false,"published_at":"2026-06-06T18:16:53.243+00:00","url":"https://junglewise.ai/threats/cve-2026-11440-theonedev-onedev-improper-authorization-in-rest-api-default"},{"cve":"CVE-2026-11439","cvss":6.3,"slug":"cve-2026-11439-theonedev-onedev-improper-authorization-in-parent-project-handler","title":"theonedev OneDev improper authorization in Parent Project Handler","severity":"medium","exploited":false,"published_at":"2026-06-06T18:16:53.063+00:00","url":"https://junglewise.ai/threats/cve-2026-11439-theonedev-onedev-improper-authorization-in-parent-project-handler"},{"cve":"CVE-2026-11438","cvss":6.3,"slug":"cve-2026-11438-theonedev-onedev-improper-authorization-in-project-fork","title":"theonedev OneDev improper authorization in project fork functionality","severity":"medium","exploited":false,"published_at":"2026-06-06T17:16:41.713+00:00","url":"https://junglewise.ai/threats/cve-2026-11438-theonedev-onedev-improper-authorization-in-project-fork"},{"cve":"CVE-2026-49248","cvss":8.3,"slug":"cve-2026-49248-onedev-arbitrary-file-write-via-absolute-path-symlink-in-tarutils","title":"OneDev arbitrary file write via absolute path symlink in TarUtils","severity":"info","exploited":false,"published_at":"2026-06-18T21:16:29.5+00:00","url":"https://junglewise.ai/threats/cve-2026-49248-onedev-arbitrary-file-write-via-absolute-path-symlink-in-tarutils"},{"cve":"CVE-2026-44647","cvss":7.1,"slug":"cve-2026-44647-onedev-path-traversal-in-git-lfs-pointer-resolution","title":"OneDev path traversal in Git LFS pointer resolution","severity":"info","exploited":false,"published_at":"2026-05-14T21:16:46.967+00:00","url":"https://junglewise.ai/threats/cve-2026-44647-onedev-path-traversal-in-git-lfs-pointer-resolution"}],"generated_at":"2026-09-26T09:11:00.170868+00:00","technologies":[{"name":"OneDev","slug":"onedev","vulnerabilities":6,"url":"https://junglewise.ai/threats/technologies/onedev"}]}